This application requires Javascript for optimal performance.

TCP.With.FIN.Flag.Only

Release Date

Jul 14, 2010

Severity

low

Impact

Fingerprinting
Security Bypass

Description

This indicates TCP packets with the FIN flag only ("TCP Headers With FIN Only"). Normally, TCP FIN packets also have the ACK flag to acknowledge the previous packet received.

"TCP FIN Without ACK" can be used to do FIN scan or evade detection.

Affected Products

Any Operating System may be affected.

Recommended Actions

If required, this signature's action can be set to "Block" to drop such packets.

Coverage

IPS
VCM

Reference: VID-23753